Ease of access security hole
There is a bug in the ease of access feature which can allow it to open a command prompt or regedit or msconfig... you catch my drift. I have been able to gain full access to the system without logging on and have been able to gain full desktop access under the context of the nt-authority\system account. Obviously, I will not disclose how this is done (except to a MS technical consultant) but I would like to know if MS are aware of this yet and also has anyone had their system comprimised yet in this manor?
November 5th, 2007 11:11pm

Hi Williams, Thank you for using Vista. Also, we do appreciate that you let us know this issue. Actually, Microsoft is always striving to capture any feedback from our partners and customers so as to ensure that we are continuously developing Microsoft products that meet our customer needs. Feedback such as yours is always taken very seriously. If it is a potential security vulnerability issue, please help report it to our Microsoft Security Resource Center to work directly with Microsoft. If possible, please also attach the detailed steps to reproduce the issue. The more information you can provide, the better. Report a Security Vulnerability http://www.microsoft.com/technet/security/bulletin/alertus.aspx Thanks again! Sincerely, Joson Zhou Microsoft Online Community Support
Free Windows Admin Tool Kit Click here and download it now
November 7th, 2007 1:16pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics